Linux Kernel BPF Scalar Zero Spill Downgrade Vulnerability
CVE-2026-98132 Published on September 25, 2026
bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO
In the Linux kernel, the following vulnerability has been resolved:
bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO
states.c:__clean_func_state() can downgrade scalar zero spill to
STACK_ZERO in the following case:
*(u64 *)(r10 - 8) = 0;
... checkpoint ...
r1 = *(u32 *)(r10 - 4);
... no reads from r10-8 ...
Here 4 bytes at r10-8 are dead and verifier changes scalar spill to a
combination: 0000pppp (p stands for poison). Such a change breaks
precision propagation chains. All places that produce STACK_ZERO
should call bpf_mark_chain_precision() for the zero source.
This patch fixes the bug in a simplest way possible:
avoids converting stack spills of zero to STACK_ZERO.
Two smarter approaches are possible:
- do bpf_mark_chain_precision() from __clean_func_state()
- check slot liveness information in check_stack_write_fixed_off()
I investigated both and the changes required are a bit tricky,
hence go with a simple fix for the time being.
Products Associated with CVE-2026-98132
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version be23266b4a08540aa43d8503a2ea10247c8daebe and below 436fa689630b741a77ef8c4a6f426479affd5bac is affected.
- Version be23266b4a08540aa43d8503a2ea10247c8daebe and below 2f3536bff8823d3c5fdbbe15e17bfca696cc2b2e is affected.
- Version 7.1 is affected.
- Before 7.1 is unaffected.
- Version 7.2.7, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.